<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS Error messages in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-error-messages/m-p/1271578#M348166</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The RADIUS protocol includes a message-id field so that the server can spot re-sent packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you see the 1st message it means ACS is seeing message ids that it thinks are currently processing (it has a list of open ids)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was going to say the most likely cause is an overly aggressive re-try timeout in the WLCS... but you've got that set to 30 seconds which should be enough.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looks to me like something in the ACS backend is hanging which is then causing a cascade of errors like you are seeing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 2nd message is a result of incoming packets being dropped by ACS. It will result in EAP conversations with bits missing or out of sequence.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you back off so that just a few clients are authenticated correctly then increase the number?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Nov 2009 11:42:08 GMT</pubDate>
    <dc:creator>darpotter</dc:creator>
    <dc:date>2009-11-09T11:42:08Z</dc:date>
    <item>
      <title>ACS Error messages</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-error-messages/m-p/1271577#M348122</link>
      <description>&lt;P&gt;Hello -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am receiving the following two ACS failed attempts logs for wireless clients connecting to WLAN using WPA1/PEAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"NAS duplicated authentication attempt"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"EAP-TLS or PEAP authentication failed during SSL handshake"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am seeing these messages for many clients. Same clients show both messages at times. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The clients fail authentication and then will succeed at random.&lt;/P&gt;&lt;P&gt;I am seeing constant flow of these at all times though.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wonder if the ACS is overwhelmed as we have added 770 new clients that use WPA/PEAP recently.  It is these clients that most often show up in the log.  But other clients show up too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the ACS Radius Authentication server timeout set to the max (30 secs) on the WLCS...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone know what these messages indicate?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I determine if the ACS svr is overwhelmed?  Is there a way to quantify it's load?  For example, how many requests per second can it handle? etc....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any design guides on redundant/HA ACS designs for 1000s of clients?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any input is appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:46:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-error-messages/m-p/1271577#M348122</guid>
      <dc:creator>c.fuller</dc:creator>
      <dc:date>2019-03-10T23:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Error messages</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-error-messages/m-p/1271578#M348166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The RADIUS protocol includes a message-id field so that the server can spot re-sent packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you see the 1st message it means ACS is seeing message ids that it thinks are currently processing (it has a list of open ids)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was going to say the most likely cause is an overly aggressive re-try timeout in the WLCS... but you've got that set to 30 seconds which should be enough.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looks to me like something in the ACS backend is hanging which is then causing a cascade of errors like you are seeing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 2nd message is a result of incoming packets being dropped by ACS. It will result in EAP conversations with bits missing or out of sequence.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you back off so that just a few clients are authenticated correctly then increase the number?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Nov 2009 11:42:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-error-messages/m-p/1271578#M348166</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2009-11-09T11:42:08Z</dc:date>
    </item>
  </channel>
</rss>

